Privacy Policy BehaviorQuant Applications
Last modified: July 17, 2026
When you use a BehaviorQuant application, we process personal data as described below. This Privacy Policy applies to BQ Advisory, BQ Performance, BQ Select, BQ Benchmark and BQ Certificate, as well as the related portals, dialogues, reports, dashboards, imports, exports, interfaces and support services. A separate Website Privacy Policy applies to the public website, website cookies, newsletters and general marketing activities.
1. Information about the Data Controller
The entity responsible for processing under data protection law depends on how the relevant solution is used.
If you are invited by a financial advisor, credit institution, investment firm, employer, asset allocator, or another organization, that organization generally determines the purposes and essential means of the processing. It is the controller within the meaning of the General Data Protection Regulation (GDPR). BehaviorQuant regularly processes the data to provide the respective BQ application as a data processor in accordance with the documented instructions provided by this BehaviorQuant customer.
The controller’s name and contact details are provided in the invitation, dialogue, portal, contract or a supplementary privacy notice. If this information is missing, you may contact BehaviorQuant; we will forward your request to the relevant entity.
BehaviorQuant acts as the controller where we determine the purposes and means of processing ourselves. This applies in particular to services contracted directly with BehaviorQuant, such as BQ Benchmark or BQ Certificate; user, administrator and license accounts; contract communications; support; billing and payment processing; IT security; analysis of misuse and errors; compliance with legal obligations; the establishment, exercise or defense of legal claims; and necessary product-related communications. Optional communications are sent only where supported by an appropriate legal basis.
2. Scope and Sources of Data
Depending on the application, this Privacy Policy applies to clients of financial advisors; financial advisors; administrators; assistants and service staff; Investment Professionals; team members; managers; fund managers; candidates and other assessed individuals; direct users of BQ Benchmark or BQ Certificate; and contacts at customers, prospects and business partners.
We obtain data directly from you; from the inviting or commissioning organization; through imports, agreed data migrations, exports, APIs or other agreed interfaces; and automatically when you use the services. Additional data are generated through calculations and inferences from the information you provide, such as profiles, scores, comparisons, fit scores, predictions and recommendations.
3. Personal Data Collected and Processed
The scope depends on the product, contract, your role and the enabled features. In particular, we may process the following data:
- Identity, contact and user account data: name, email address, telephone number, postal address, organization, role, language, internal user or client ID, login data and access permissions.
- Dialogue, assessment and simulation data: responses to questions, tasks and scenarios; hypothetical or intended investment decisions; knowledge and experience; timestamps; completion times; and response behavior.
- Behavioral, preference and profile data: risk attitudes, perceptions, personality, values, interests, sustainability preferences, decision-making and information-processing style, biases, sentiment and behavioral tendencies.
- Financial and investment data: investment objectives, financial situation, investment amount, share of total wealth, investment period, portfolio composition, investment components, allocations, volatility, maximum losses and risk scores.
- Professional, team and organizational data: age or age group, gender, education, professional background, position, professional experience, country of employment, team assignment, and organization type and size.
- Results and derived data: profiles, scores, fit scores and comparison metrics, risk tolerance, risk capacity, Client Risk Scores, Portfolio Risk Scores, performance drivers, performance inhibitors, team and candidate comparisons, predictions and recommendations.
- Import, export, usage and security data: contact lists, client assignments, portfolio data, technical identifiers, API and data-transfer logs, email sending and delivery status, IP address, browser, device, operating system, and session, login, access, error and security logs.
- Communication, contract, payment and AI data: support requests, emails, call and meeting notes, license, contract and billing information, payment method and transaction status and, where AI features are enabled, selected attributes, technical codes, prompt and context data, generated text and feedback. Full payment details are generally processed by the payment service provider.
We currently use timestamps and resulting completion times or response speeds primarily for technical and scientific quality checks. Any systematic use in scores or personalized recommendations will be disclosed transparently in advance.
BehaviorQuant applications are not designed to collect special categories of personal data under Article 9 GDPR or personal data relating to criminal convictions and offenses under Article 10 GDPR.
4. Purpose of Data Processing
We process data to invite, register and authenticate users; conduct dialogues, assessments, tasks, scenarios and simulations; calculate profiles, scores, fit assessments, predictions and comparisons; and create reports, dashboards, certificates, E-Badges and advisor- or team-related guidance. This also includes displaying and analyzing portfolios, supporting advisory, communication, team, selection and decision-making processes, and providing agreed imports, exports and interfaces.
Further purposes include customer service, support, training, error analysis, quality assurance, IT security, access control, misuse prevention, logging, recovery, contract and license administration, billing, payment processing, compliance with legal obligations, and the establishment, exercise or defense of legal claims. Product and methodology improvements are carried out only where covered by the applicable legal basis, documented instructions and contractual arrangements, or using irreversibly anonymized data.
5. Product-specific Processing
BQ Advisory
BQ Advisory helps financial advisors, banks and investment firms understand their clients better and tailor advice and communication to their circumstances. In particular, it processes information and results relating to risk tolerance, risk capacity, the Client Risk Score, investment objectives, financial situation, investment period, values, preferences, sustainability, decision-making behavior and behavioral advisory indicators.
Depending on the license and enabled features, we may also process investment details; sample, company and client portfolios; investment components; allocations; Portfolio Risk Scores; historical risk and return data; and the alignment between client and portfolio risk. Results may appear in the client report, advisor dashboard or advisor-only guidance. They support preparation for client meetings, documentation and ongoing client service. Investment decisions are made by the advisor or client, not by BehaviorQuant.
BQ Performance
BQ Performance analyzes the decision-making and behavioral patterns of Investment Professionals and teams. Questions, tasks and scenarios generate individual profiles, performance drivers and performance inhibitors, insights into strengths and risks, team comparisons, complementarity and fit analyses, and recommendations for improving decision-making processes. Repeated dialogues can show changes over time.
The individual and team results that participants, team leads, employers or other authorized persons can access depend on the contract, role and product configuration. The invitation or a product-specific notice explains the applicable access arrangements.
BQ Select
BQ Select supports the assessment and comparison of Investment Professionals, fund managers, teams and, where agreed, candidates. Algorithms compare profiles and results against the customer’s requirements or weightings and show matches, differences, strengths and potential risks. The results are decision-support information. Selection, exclusion, hiring, promotion, compensation and other significant decisions must be made by responsible human decision-makers and be subject to a meaningful, traceable review.
The customer using BQ Select is responsible for the lawfulness of the specific selection or employment purpose, the legal basis, informing data subjects, preventing discriminatory use and providing effective human oversight. Where required, additional product-specific information and safeguards will be provided.
BQ Benchmark
BQ Benchmark enables Investment Professionals to complete a direct self-assessment and compare their results with reference groups. We process user account and assessment data and the resulting benchmark, map and report results. Where users register directly, BehaviorQuant generally acts as the controller. By default, results are accessible only through the relevant user account; limited access by authorized support or technical personnel may be necessary to provide the service or troubleshoot issues.
BQ Certificate
BQ Certificate documents the regular use of agreed BehaviorQuant services and may include a digital or printed certificate and an E-Badge. For this purpose, we process identity, contact, organization, participation, validity and, where applicable, shipping data. A personal certificate or E-Badge is generally published by the individual concerned or with their authorization. For corporate or team certificates, the allocation of responsibilities agreed in the contract applies.
Imports, exports, APIs and integrations
Where interfaces have been agreed, data may be imported from customer systems or transferred to those systems on the customer’s instructions. The customer determines the recipients, purpose and permissions and is responsible for further processing in its systems. BehaviorQuant processes technical logs to support data transmission, security and troubleshooting. New integrations, particularly for external AI systems or future MCP features, will be enabled only after a separate data protection and security review and an update to the relevant privacy information.
6. Visibility of Data and Results
Access is limited to persons and entities that need it for their tasks and are authorized to have it. Depending on the context, these may include you; the inviting advisor and authorized users of the controller; administrators; team or selection decision-makers; expressly authorized assistants and service staff; BehaviorQuant personnel in support, operations, security, development or data science; contracted service providers; and payment service providers, tax advisors, legal advisors, auditors and public authorities. Other recipients receive data only with your authorization, on the controller’s instructions or where required by law.
The specific access rights depend on the product, role, contract and configuration. The product interface does not always display every raw response, timestamp or intermediate technical result. Statutory rights of access remain unaffected; whether specific raw data must be disclosed is assessed case by case under Article 15 GDPR, taking into account the rights and freedoms of others.
7. Automated Processing, Profiling and AI
BehaviorQuant uses statistical and psychometric methods and machine-learning models to calculate profiles, scores, fit assessments, comparisons and predictions based on information you provide and contextual data. This may constitute profiling within the meaning of the GDPR. Calculations follow defined rules, weightings, norms and reference groups; overall scores therefore need not equal the simple average of visible component scores. The methodology is explained in plain language in product information, reports or on request, to the extent that this does not adversely affect trade secrets or the rights of third parties.
BehaviorQuant does not make decisions on this basis that are based solely on automated processing and produce legal effects concerning you or similarly significantly affect you. The results are information and decision-support tools. Where consequences may be significant, particularly in selection, employment or financial contexts, a qualified person must consider additional information and take responsibility for the decision. Any future use of decisions based solely on automated processing will occur only after a separate assessment, appropriate safeguards and specific notice; where Article 22 GDPR applies, you have, in particular, the right to obtain human intervention, express your point of view and contest the decision.
Profiles, scores and predictions are calculated mainly using BehaviorQuant’s own models within the BehaviorQuant environment. For expressly enabled text-generation, summarization or advisor-support features, BehaviorQuant may use external generative AI services. Only the data required for the relevant purpose are transmitted; direct identifiers are generally removed or replaced. As long as the data can be attributed to an individual, we treat them as pseudonymized personal data. The current list of sub-processors identifies the providers, purpose of use, and processing locations.
AI-generated content may be incomplete or inaccurate. It is provided as a suggestion, must be reviewed by a qualified professional and must not be used without review as a binding recommendation, selection decision or other significant decision. Obligations under the EU AI Act depend on the intended use of the relevant feature. BehaviorQuant complies with the obligations applicable to its role; customers must comply with those applicable to their specific use.
8. Legal Bases for Processing
Where BehaviorQuant processes personal data on behalf of a customer, that customer, as controller, determines the legal basis. Depending on the context, the legal basis may be performance of a contract, steps taken before entering into a contract, compliance with a legal obligation, legitimate interests, consent or supplementary employment-law provisions. The controller must inform you of the specific legal basis. BehaviorQuant processes the data under the Data Processing Agreement and documented instructions.
Where BehaviorQuant acts as the controller, processing is based in particular on Article 6(1)(b) GDPR for performance of a contract and steps taken before entering into a contract; Article 6(1)(c) GDPR for compliance with legal obligations; Article 6(1)(f) GDPR for IT security, misuse prevention, technical quality, support documentation, defense of legal claims and appropriate B2B communications; and Article 6(1)(a) GDPR where consent is required. Consent is voluntary and may be withdrawn at any time with effect for the future.
Mandatory fields are required to provide the relevant service or perform the contract. Without this information, it may not be possible to complete a dialogue, generate a report, create an account, issue a certificate or process a payment. Voluntary information is identified as such. BehaviorQuant does not itself impose a general legal requirement to participate in a BehaviorQuant assessment; the customer using the solution will inform you of any specific requirements or consequences in its context.
9. Service Providers, Transfers to Third Countries and Cookies
BehaviorQuant engages carefully selected service providers and contractually requires processors to comply with data protection, confidentiality, security and documented instructions. The current list of sub-processors is available at behaviorquant.com/en/dpa/#sub.
Typical services include Google Cloud Platform for hosting and infrastructure; the current email service provider for invitations and system messages; Microsoft 365 for communication and collaboration; Stripe for payments; and, where enabled, OpenAI or another approved provider of generative AI services. Stripe may process some payment data as an independent controller. Website services such as HubSpot, Hotjar, Google Analytics or Typeform are covered by this Privacy Policy only if they are actually used in authenticated product areas; otherwise, the Website Privacy Policy applies.
We aim to process personal data within the European Union or the European Economic Area (EEA). With global service providers, processing or support access outside the EEA cannot always be excluded. Such transfers take place in accordance with Articles 44 to 49 GDPR, in particular on the basis of an adequacy decision, the EU-U.S. Data Privacy Framework, Standard Contractual Clauses and, where necessary, supplementary measures. You may request information about the safeguard used in a specific case from the controller or BehaviorQuant.
The applications use strictly necessary cookies or similar storage technologies for login, session management, language settings, security and selected functions. Optional analytics or convenience features are used only where enabled, legally permissible and, where required, covered by your consent. Website cookies and website marketing are outside the scope of this Privacy Policy.
10. Retention, Deletion and Anonymization
We retain personal data only for as long as necessary for the relevant purpose, the contract, documented instructions, legal obligations or legal claims. The data are then deleted or, where legally permitted, anonymized in a genuinely irreversible manner. Data subject to statutory retention requirements are processed only for those purposes.
- B2B assessment, profile, portfolio and results data: for the duration of the customer contract, followed by an export or return period of up to three months. Unless documented instructions or a legal obligation require otherwise, BehaviorQuant then deletes the data automatically without any further separate instruction.
- Direct user accounts, BQ Benchmark and certificate services contracted directly: until the account is deleted or the contract ends, and generally for no more than a further three months, unless a legal obligation or outstanding service requires longer retention.
- AI inputs and outputs: generally for as long as the associated profile, account or result exists. The external provider’s contractually and technically configured retention periods apply; technical security or abuse-prevention logs may be retained temporarily.
- Payment, invoicing and accounting data: generally for seven years after the end of the relevant calendar year, and longer where required by law or legal proceedings.
- Support and contract communications, security, access and error logs, and backups: only for as long as necessary to handle the matter, preserve evidence, operate and secure the services, analyze errors or pursue legal claims. Following a security incident, retention may continue until the investigation and any related proceedings are concluded. Backups are overwritten in accordance with the documented rotation cycle and are not used for new purposes.
Where contractually permitted and lawful, BehaviorQuant may anonymize data before deletion so that it can no longer be attributed to an individual or customer organization and re-identification is no longer reasonably possible using reasonably available means. Replacing a name with a code is pseudonymization only.
Irreversibly anonymized data may be used over the longer term for scientific analysis, product and methodology development, quality assurance and improvement of statistical and machine-learning methods. Personal data or data that are merely pseudonymized are provided to research institutions for their own purposes only on a separate legal basis, under contractual arrangements and with appropriate notice.
11. How We Protect Your Data
BehaviorQuant implements technical and organizational measures appropriate to the risk. These include, in particular, role-based access controls, authentication, secure password storage, encryption in transit, separation of roles and customer environments, confidentiality obligations, logging of security-relevant access, regular backups, vulnerability and update management, staff training, and procedures for detecting, managing and reporting security incidents. No system can guarantee absolute security. You should therefore protect login credentials, invitation links and devices and report suspicious activity without delay.
12. Your Data Protection Rights
Subject to the statutory requirements, you have, in particular, the right to: access and obtain a copy of your personal data; have inaccurate data rectified; have data erased; restrict processing; exercise data portability; object to processing based on legitimate interests and, at any time, to direct marketing; withdraw consent with effect for the future; not be subject to a decision based solely on automated processing within the meaning of Article 22 GDPR; and lodge a complaint with a supervisory authority.
Where BehaviorQuant processes data on behalf of a customer, please contact, in the first instance, the organization that invited you. BehaviorQuant will assist that organization in handling your request. If BehaviorQuant is the controller or you do not know which entity is responsible, email dpo@behaviorquant.com or contact@behaviorquant.com. To prevent unauthorized disclosure, we may request appropriate proof of identity.
You may lodge a complaint with the supervisory authority for your habitual residence, place of work or the place of the alleged infringement. The Austrian Data Protection Authority (Österreichische Datenschutzbehörde) is, in particular, the competent supervisory authority for BehaviorQuant: Barichgasse 40-42, 1030 Vienna, Austria; email: dsb@dsb.gv.at.
13. Minors and changes to this Privacy Policy
BehaviorQuant applications are intended for adults and generally may be used only by persons aged 18 or over. We do not knowingly collect data from children. If a minor’s data are processed without an appropriate legal basis, we will coordinate the necessary steps with the controller and delete the data or restrict their processing as required by law.
We update this Privacy Policy when products, processing activities, service providers or legal requirements change. The date of the latest update appears at the beginning. We will provide appropriate notice of material changes. New processing activities, particularly new AI or integration features, will be disclosed transparently before they are enabled.
14. Contact
BehaviorQuant Behavioral Finance Technologies GmbH
Kolingasse 6/XI, 1090 Vienna, Austria
Telephone: +43 (1) 890 8418
General contact: contact@behaviorquant.com
Data protection contact: dpo@behaviorquant.com